CVE-2026-18733: Prompt injection bypasses shell tool consent gate in Strands Agents Tools
A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the noninteractive parameter to true, bypassing the human consent gate.
To remediate this issue, users should upgrade to version 0.8.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon Strands Agents Tools (shell tool)to a version that resolves this vulnerability.Fixed in 0.8.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18733?
The severity of CVE-2026-18733 is rated high with a score of 8.8.
How do I fix CVE-2026-18733?
To mitigate CVE-2026-18733, upgrade Amazon Strands Agents Tools to version 0.8.0 or later.
What does CVE-2026-18733 exploit?
CVE-2026-18733 exploits a prompt injection vulnerability in the shell tool of Amazon Strands Agents Tools.
What are the potential impacts of CVE-2026-18733?
CVE-2026-18733 allows remote actors to execute arbitrary operating system commands on the host machine.
Which software is affected by CVE-2026-18733?
CVE-2026-18733 affects Amazon Strands Agents Tools versions prior to 0.8.0.